top operator - Search Language Test (REST)
- search test: top operator through the /v3/splunk/search REST interface.
comment splunk> /v3/splunk/search - 'empty'
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search]%20|%20outputxml Perform an empty search via REST
comment Validate result 'empty'
verifyAttribute //envelope/searchResults/results/@type empty
comment **** top Simple Case ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20top%205%20processor]%20|%20outputxml Perform search via REST interface - 'index::_internal | top 5 processor'
comment Validate columns count, percent, processor
verifyText //envelope/searchResults/results/cols/col[@cd='1'] processor
verifyText //envelope/searchResults/results/cols/col[@cd='2'] count
verifyText //envelope/searchResults/results/cols/col[@cd='3'] percent
comment **** top: apache clientip Case ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::sampledata%20sourcetype::access_combined%20|%20top%2012%20clientip]%20|%20outputxml Perform search via REST interface - 'index::sampledata sourcetype::access_combined | top 12 clientip'
comment Validate columns clientip, count, percent
verifyText //envelope/searchResults/results/cols/col[@cd='1'] clientip
verifyText //envelope/searchResults/results/cols/col[@cd='2'] count
verifyText //envelope/searchResults/results/cols/col[@cd='3'] percent
comment **** top failure; simple case, no args ****
openAndWait /v3/splunk/search?q=page%200-100%20500%20[search%20index::_internal%20|%20top]%20|%20outputxml Perform search via REST interface - 'index::_internal | top'
comment Expect and validate error notification due to missing args
verifyAttribute //envelope/messages/msg/@type ERROR
verifyText //envelope/messages/msg Error*